Impact
The vulnerability is an OS command injection flaw in the configuration management subsystem of Brocade Fabric OS. When a configuration download is performed, the management daemon forwards user‑supplied strings unvalidated to an internal utility script, which interprets them in a shell command. A malicious or compromised configuration file can thus cause arbitrary operating system commands to run on the target switch, giving an attacker the ability to alter, delete, or exfiltrate data on the device.
Affected Systems
Affected products are Brocade Fabric OS obtained before version 9.2.2d and from 10.0.0 through 10.0.0a1. The vulnerability is present in all prior releases of Fabric OS 9.x and 10.x before the specified update releases.
Risk and Exploitability
The CVSS base score of 7.3 represents a high‑severity flaw. EPSS information is not reported, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to supply a configuration download request that includes a malicious relay host string or filename; the attacker typically needs a degree of control over the configuration file sent to the device or the ability to trigger the download as an administrator. The attack is likely to be local to the switch but can be triggered by a remote administrator who initiates the download with a malicious payload. Given the lack of a publicly available exploit, the actual threat remains moderate but the impact of successful exploitation is significant, allowing arbitrary OS command execution on the switch.
OpenCVE Enrichment